CVE-2026-98113

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: rate limit unmapped SID errors A client can include many structurally valid but unmapped SIDs in a DACL. Logging every mapping failure lets one request generate hundreds of kernel error messages. Rate limit the message to prevent an authenticated client from flooding the kernel log.

References

https://git.kernel.org/stable/c/feca5e70fc963b088377b20879e8cd8237c2fd7d

https://git.kernel.org/stable/c/54cb2a909996346ac6a8a3beac96c07b3dcba584

https://git.kernel.org/stable/c/30dbb08777b9a611d7d9193c040f382fbd0e7562

https://git.kernel.org/stable/c/13af319c1efec0b45fb5c1b16830eb0888b3fd1e

Details

Source: Mitre, NVD

Published: 2026-09-25

Updated: 2026-09-25

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.002